Microsoft Certified: Identity and Access Administrator AssociateImplement an identity management solutionMedium

A company is deploying Azure AD Connect to synchronize user accounts from an on-premises Active Directory. They have a complex OU structure and only want to synchronize users located in OUs named 'Sales' and 'Marketing' within a specific domain, 'contoso.com'. Users in other OUs, even within 'contoso.com', or in other domains/forests, should not be synchronized. Which synchronization filtering method should be configured in Azure AD Connect?

  1. AAttribute-based filtering
  2. BOrganizational Unit (OU) filtering
  3. CDomain-based filtering
  4. DGroup-based filtering
Show answer & explanation

Correct answer: B. Organizational Unit (OU) filtering

Organizational Unit (OU) filtering in Azure AD Connect allows administrators to select specific OUs from their on-premises Active Directory to be synchronized to Azure AD, precisely matching the requirement to sync only users in 'Sales' and 'Marketing' OUs.

Why the other options are wrong

  • A. Attribute-based filtering uses user attributes (e.g., department) but is less direct for OU-specific requirements.
  • C. Domain-based filtering synchronizes entire domains, not specific OUs within a domain.
  • D. Group-based filtering synchronizes members of specified groups, which would require managing group memberships, not OUs.

Azure AD Connect OU Filtering

A feature in Azure AD Connect that allows administrators to selectively synchronize objects based on their Organizational Unit (OU) location in the on-premises Active Directory to Azure AD.

  • Configured during initial setup or later via wizard.
  • Excludes or includes entire OUs.
  • Useful for managing scope of synchronized identities.

Memory trick: Filter the forest, only sync the chosen branches.

More Implement an identity management solution questions